2024-08-12 (Monday): #XLoader/#Formbook infection. As I've been restoring older pages on my blog with the new password scheme for the zip archives, I'm astounded at the amount of pages and details I used to post.
With that in mind, I did a blog post more in the old style, with images and IOCs listed on the blog page.
Details at: https://www.malware-traffic-analysis.net/2024/08/12/index.html
We just released a landscape review of Registered DGAs. We review the many ways threat actors are leveraging these algorithms -- including malware, phishing, scams, porns, you name it. Our RDGA detectors find tens of thousands of domains every day, and we've seen the use continue to rise over the last several years. Most folks aren't even aware since actors are doing this in DNS and it often isn't obvious. #dns #threatintel #cybersecurity #cybercrime #infoblox #RDGA #DGA #DDGA #malware #phishing #scams #infoblox #infobloxthreatintel #cybersecurity #threatactor #c2 #revolverrabbit #threatintelligence #cyber #cyberintelligence #xloader #formbook #abusedtld https://insights.infoblox.com/resources-research-report/infoblox-research-report-registered-dgas-the-prolific-new-menace-no-one-is-talking-about
Latest issue of my curated #cybersecurity and #infosec list of resources for week #34/2023 is out! It includes the following and much more:
Before jumping into this week’s infosec news, I wanted to let you guys know that this newsletter has just achieved its 1,000th subscriber! I’m so humbled and grateful to all of you who regularly read this list.
➝
#Databreach at French govt agency exposes info of 10 million people
➝ #Kroll data breach exposes info of #FTX, #BlockFi, #Genesis creditors
➝
#MOVEit, the biggest hack of the year, by the numbers
➝
HUS confirms data breach by ex-staff member, hundreds of patients' data compromised
➝
#Hosting firm says it lost all customer data after #ransomware attack
➝
Scraped data of 2.6 million #Duolingo users released on hacking forum
➝ #Ivanti warns of new actively exploited #MobileIron zero-day bug
➝
️ Japanese watchmaker #Seiko breached by #BlackCat ransomware gang
➝
#Tesla notifies employees of data breach
➝ North Korean APT Hacks Internet Infrastructure Provider via ManageEngine Flaw
➝ #Microsoft says Chinese hacking crew is targeting #Taiwan
➝
#FBI Finds 1,580 Bitcoin in #Crypto Wallets Linked to North Korean Hackers
➝
Australian Lender Latitude Financial Reports AU$76 Million #Cyberattack Costs
➝
North Korean hackers target US-South Korea military drills, police say
➝
#Pentagon urges US space companies to stay vigilant against foreign intelligence
➝
Two #LAPSUS$ Hackers Convicted in London Court for High-Profile Tech Firm Hacks
➝
Two founders behind Russian crypto mixer Tornado Cash charged by US federal courts
➝
US tech firms offer data protections for Europeans to comply with EU big tech rules
➝
Brazilian Hacker Claims #Bolsonaro Asked Him to Hack Into the Voting System Ahead of 2022 Vote
➝
#FBI: Patches for Recent #Barracuda ESG Zero-Day Ineffective
➝ New #Malware Turns #Windows and #macOS Devices into Proxy Nodes
➝
New Variant of #XLoader macOS Malware Disguised as 'OfficeNote' Productivity App
➝
Researchers Uncover Real Identity of CypherRAT and CraxsRAT Malware Developer
➝
#Google Workspace Introduces New AI-Powered Security Controls
➝
#Bitwarden releases free and open-source E2EE Secrets Manager
➝
Meta plans to roll out default end-to-end encryption for Messenger by the end of the year
➝
TP-Link smart bulbs can let hackers steal your WiFi password
➝
#WinRAR flaw lets hackers run programs when you open RAR archives
This week's recommended reading is: "Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World" by Bruce Schneier
Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end
https://infosec-mashup.santolaria.net/p/infosec-mashup-week-342023